IP Library Granted Patent US 8,484,753
Granted Patent B2
US 8,484,753 · App. 12/629,330 · Granted Jul 9, 2013

Hooking nonexported functions by the offset of the function

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,484,753
App. No.
12/629,330
Granted
Jul 9, 2013
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for obfuscated malware. In one aspect, a method includes accessing offset data associated with a binary executable, the offset data including an offset of a nonexported function; and modifying instructions at the offset. In another aspect, a method includes analyzing a reference generated for a binary executable, identifying a unique identifier for the binary executable, determining an offset of a nonexported function in the binary executable, and generating offset data that includes the offset and the unique identifier.

Claims (34)

1. A computer-implemented method, comprising:

identifying that a binary executable in a host computer memory includes a nonexported function with a particular vulnerability, the binary executable being allocated memory space in the host computer memory, the memory space addressed at a first memory location;

accessing offset data associated with the binary executable, the offset data identifying an offset that defines a second memory location relative to the first memory location, the second memory location different from the first memory location, the second memory location storing the nonexported function within the binary executable; and

modifying instructions at the second memory location to route a code path to a host protection processor.

2. The method of claim 1 , wherein the nonexported function is called by an exported function.

3. The method of claim 1 , wherein accessing offset data comprises:

identifying a hash ID that uniquely identifies the binary executable; and

identifying an offset associated with the binary executable based on the hash ID.

4. The method of claim 1 , wherein the offset data further comprises a version string for the binary executable.

5. The method of claim 1 , wherein the offset data further comprises a byte pattern adjacent to the offset.

6. A computer-implemented method, comprising:

analyzing, using at least one processor device, a reference file generated for a binary executable determined to have a particular vulnerability, the reference file containing a representation of instructions that are in the binary executable;

identifying a unique identifier for the binary executable;

locating a nonexported function corresponding to the particular vulnerability in the binary executable from the analysis of the reference file;

determining an offset for the nonexported function, the offset being the number of bytes between the nonexported function and the beginning of the binary executable; and

generating offset data that includes the offset and the unique identifier.

7. The method of claim 6 , wherein the reference file is a symbol file.

8. The method of claim 6 , wherein the offset data further comprises a version string for the binary executable.

9. The method of claim 6 , wherein the offset data further comprises a byte pattern adjacent to the offset.

10. A system, comprising:

a processor device;

a memory element; and

a file analyzer configured, when executed by the processor device, to analyze a reference file generated for a binary executable determined to have a particular vulnerability, the reference file comprising a representation of instructions that are in the binary executable; locate a nonexported function corresponding to the particular vulnerability in the reference file; and determine an offset for the nonexported function, the offset being the number of bytes between the nonexported function and the beginning of the binary executable.

11. A system, comprising:

a host computer memory configured to store data for a computer;

a hook by offset engine that performs operations comprising:

identifying that a binary executable in a host computer memory includes a nonexported function with a particular vulnerability, the binary executable being allocated memory space in the host computer memory, the memory space addressed at a first memory location;

accesses offset data associated with the binary executable, the offset data identifying an offset that defines a second memory location relative to the first memory location, the second memory location storing the nonexported function within the binary executable; and

modifies instructions at the second memory location to route a code path to a host protection processor.

a host protection processor that performs operations comprising:

determining whether execution of the nonexported function would result in exploitation of the particular vulnerability; and

determining whether to allow execution of the nonexported function

12. The system of claim 11 , wherein determining whether execution of the nonexported function would result in exploitation of the particular vulnerability includes monitoring for attempts to exploit the particular vulnerability.

13. The system of claim 11 , wherein the host protection process is adapted to prevent the execution of the nonexported function.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2009
From: NOJIRI, DAISUKE
To: MCAFEE, INC.
Reel/Frame 023693/0342 →